Health care apps - part 2 of 2: delving into data confidentiality
How to protect confidentiality of data by putting in place proper contractual arrangements, setting out how a party may use any information or data associated with the App during its development and prior to it being made available on the market.
The adoption of smart technology solutions by the health and care sector has exploded in 2020. The pandemic has driven the sector to increase its use of smart phone technology solutions (“Apps”), an example of which is conducting video consultations and assessments. Adoption has historically been slow to develop across the sector generally, potentially due to perceived risks in maintaining integrity of special category personal data.
Now that more health and care providers are transitioning to greater use of Apps, the Covid-19 pandemic has propelled providers to implement systems which can assess an individual’s needs remotely.
In the ‘new normal’, the sector will increasingly adopt and implement the use of Apps to assess and deliver person-centric health and well-being advice and services. The Apps which are created will be in demand, competition is likely to be high and the potential commercial value to providers is significant.
Apps are created by combining software with data (in its broadest sense and by use of personal data). Part 1 of this 2-part series explored how intellectual property rights in Apps might be protected commercially. Part 2 will delve into how to protect confidentiality of data by putting in place proper contractual arrangements which set out how a party may use any information or data associated with the App during its development and prior to it being made available on the market.
Data confidentiality
A successful health and social care App must ensure data confidentiality. Any failure to do so may result in a data breach, resulting in potential claims by individuals affected as well as an investigation and potential fine from the ICO or other regulators. That is without taking account of the reputational damage, which would likely reduce consumer confidence in the product and company which will consequently impact on revenue and the ability to enter the supply chain (particularly with large organisations such as the NHS).
Use of personal data should always be minimised (e.g. limited to data needed to achieve the intended purpose) and anonymised data should be used where possible. However, use of personal data is likely necessary for health care Apps. A potential solution to address the risk of being victim to a cyberattack and potential data breach is to apply cryptographic algorithms to encrypt data. Cryptographic algorithms are used for tasks including data encryption and authentication. The benefit to using cryptographic algorithms being that if exchanged data is intercepted, the attacker is not able to understand the content, so the risk is reduced.
When designing an App, you should ensure that the confidentiality of any personal data is properly managed by applying the following measures and ensuring these are reviewed and managed whilst the App is in use:
- data minimisation (e.g. only collect data which is necessary for the purpose) and review the amount of data collected periodically;
- data utilisation (e.g. using the data only in accordance with the purposes for which it was collected and in accordance with appropriate privacy policies);
- encryption (e.g. the process which renders data unreadable);
- managing data access and revocation (e.g. controlling access and limiting access to those on a strict ‘need to know’ basis, with users being required to have strong passwords and two-factor authentication where possible);
- managing physical security of devices and physical and electronic documentation as well as general computer use management (e.g. use of anti-virus software, routine patching, password protected devices and application access by users, suspension of session inactivity and enabling firewall);
- ensuring appropriate destruction (and deletion from electronic devices and cloud services or similar) of data once the purposes for which it was provided has expired or is no longer reasonable.
If engaging third party software developers, you should ensure robust obligations of confidentiality are also put in place, including, for example, the purposes for which information can be used and its restrictions on use.
The benefit of having such obligations in place is that if data is shared, either purposefully or accidentally, during App design and development, the risk that there is misuse of the data (which offers a commercial advantage rather than a bad faith use of personal data) can be addressed by having an enforceable right against that third party to (i) seek an injunction preventing further use; and (ii) claim damages for breach of contract. To the extent any registrable intellectual property right subsists in the App (which is prevented due to prior disclosure), you may have a remedy to pursue such registration if it can be established that the disclosure was made in breach of confidence.
Conclusion
Apps have a valuable place in the healthcare market and will likely continue to attract significant investment to produce better ways of delivering healthcare solutions. However, failing to address the above risks prior to starting App development has the potential to thwart any project timelines for implementation and commercialisation, but is also at increased risk of being subject to a future dispute and potential breach of an individual’s data rights.
Contact

Richard Nicholas
Partner
richard.nicholas@brownejacobson.com
+44 (0)121 237 3992
Related expertise
You may be interested in...
Opinion - Maternity services
University Hospital Leicester hold their inaugural Maternity Safety Conference
In Person Event
Navigating your way through high profile sensitive reviews and investigations
Opinion
Junior doctors vote unanimously in favour of strike action
Opinion
Can toilet facilities amount to sex discrimination?
Published Article
Digital Twin Technologies: key legal contractual considerations
Opinion
Consultation launched on minimum ambulance service levels during strike action
Opinion - Maternity services
Changes to redundancy protections for employees post-maternity leave
Legal Update - Shared Insights
Shared Insights: Coroners’ Question Time
Press Release - Careers
Browne Jacobson health lawyer wins major accolade at Made in Manchester Awards
Opinion
BMA issues medical locum rate card for junior doctors
Legal Update
Employee who refused to wear a face mask fairly dismissed
Opinion
New toolkit to support safer recruitment in the care sector
Legal Update
Green Leases for the NHS
Guide
Government response to the consultation on the Higher-Risk Buildings Regulations
Published Article
The first 100 days for Integrated Care Boards
Opinion
Menopause and the workplace
On-Demand
Future of Care - Retirement Living webinar
In Person Event
Independent Healthcare In-House Lawyers Forum
Opinion
Government introduces new “anti-striking laws” to be discussed in Parliament
Press Release - Maternity services
Father Christmas comes to University Hospital Coventry and Warwickshire care of Browne Jacobson’s Birmingham Office Community Action Group
Opinion - Maternity services
The Patient Safety Incident Response Framework (PSIRF) and its impact on maternity services
Legal Update - Shared Insights
Shared Insights: Looking ahead to 2023 – what Health and Care employers need to know
Opinion
Coroner’s refusal to issue a Prevention of Future Deaths Report following death in prison custody inquest was lawful
Article
Mental health, eating disorders and placement of young people
Legal Update
LPS consultation and ‘go live’ planning
Opinion
Consultation launched on plans to amend NHS pension rules to bolster NHS workforce
Legal Update
Getting ready to face Industrial Action
Legal Update - Shared Insights
Shared Insights: Prolonged disorders of consciousness
Published Article
How AI and technology can transform the healthcare sector
On-Demand
The UK's green agenda - the outcomes of COP27 and actions since COP26
On-Demand
Insights from the Chief Coroner by His Honour Judge Thomas Teague, KC
Opinion
BMA advises consultants not to accept less than the BMA minimum rate card for extra-contractual work
The BMA is advising all NHS / HSCNI consultants to ensure extra-contractual work is paid at the BMA minimum recommended rate and to decline offers of extra-contractual work that doesn't value them appropriately.
On-Demand
Leadership and lessons learnt during the Pandemic by Professor Jonathan Van-Tam
Legal Update - Shared Insights
Shared Insights: The Patient Safety Incident Response Framework
Guide - Maternity services
Mediation guide for Clinicians: What do you need to know and how do you need to prepare
Opinion
NHS England – Updated Transaction Guidance
NHS England has published (October 2022) new guidance - Assuring and supporting complex change: Statutory transactions, including mergers and acquisitions.
Opinion
NHS England – Assuring and supporting complex change
NHS England has issued an updated (publication 11 October 2022) suite of Complex Change guidance about how it will assure and support proposals for complex change that are reportable to it. New and (where it is still in force) existing Complex Change guidance are as follows.
Legal Update
The Retained EU Law
Created at the end of the Brexit transition period, Retained EU Law is a category of domestic law that consists of EU-derived legislation retained in our domestic legal framework by the European Union (Withdrawal) Act 2018. This was never intended to be a permanent arrangement as parliament promised to deal with retained EU law through the Retained EU Law (Revocation and Reform) Bill (the “Bill”).
Legal Update
Economic crime and cybercrime
It is clear that the digital landscape, often termed cyberspace, is a man-made environment, in which human behaviour dominates and where technology both influences and aids our role in it — through the internet, telecoms and networked computer systems, which are often interdependent. The extent to which any organisation is potentially vulnerable to cyber-attack depends on how well these elements are aligned.
Legal Update
Redundancy consultation and selection concerning expiry of a fixed term contract – EAT put the spotlight onto a ‘selection pool of one’
In Mogane v Bradford Teaching Hospitals NHS Foundation Trust the Employment Appeal Tribunal (EAT) considered whether it was fair to dismiss a nurse as redundant on the basis that that her fixed-term contract was due to expire before that of her colleague.